AUTONOMOUS SECURITY TESTING · APPLICATION · CLOUD · NETWORKEST. 2025
REPRODUCIBLE · PUBLIC BENCHMARK · LIVE ESTATES

Every number here came from a run.

Nothing below is a projection. Where a figure is approximate we say so, and where it comes from outside research we name who published it.

1,000+
ways in proven across customer estates in a single weekend, 50× a specialist team
94.1%
of a public benchmark's known weaknesses caught in one pass
Half
of everything it proves is critical severity, not noise to triage
01BENCHMARK · OWASP JUICE SHOP
GREYBOX · SINGLE RUN
94.1%

of benchmark vulnerability classes surfaced in one autonomous pass, each finding reproduced and scored before it was reported.

BLACKBOX · COVERAGE BY ROUND
Three rounds70.6%
Six rounds82.4%

Memory is why the second figure exists. The same target, tested again, yields more because everything prior is retained rather than rediscovered.

02VELOCITY · ONE 72 HOUR WINDOW
1,000+

verified findings, across more than twenty subdomains tested in parallel, with no human operator in the loop.

50×faster than one human pentester over the same window
20+subdomains, parallel
~14/hrfindings, continuous
72 hrsstart to finish
SAME THREE DAYS · FINDINGS DELIVERED
One human pentester, one app~201× BASELINE
Boutique team of three~603× FASTER
Orwell, all subdomains1,000+50× FASTER

Roughly fifty times the output of a full boutique team over the same three days. A year of conventional testing, delivered over a long weekend, then repeated the following week.

CUMULATIVE FINDINGS OVER THE WINDOW
HOUR 0HOUR 36HOUR 72 · 1,000+
03WHAT IT ACTUALLY FINDS

The kinds of things it turns up.

Not theory. These are the classes of problem Cipher proves again and again across the estates it runs on, and the ones most likely to end up in a breach report.

WHERE THEY TURN UP
Your apps and APIsMOST OFTEN
Cloud and infrastructureOFTEN
Systems nobody owns any moreALWAYS
Between two systems that trust each otherTHE WORST ONES
EXAMPLES IT HAS PROVEN
Logins that can be walked past

Signing in as any account without ever knowing the password.

Databases open to the internet

Live customer data sitting there for anyone who knows the address.

One customer reading another's data

Change a number in a request and someone else's records come back.

Keys left where anyone can pick them up

Working credentials retrievable with no access to start from.

Old software nobody updated

A version with a published exploit, still facing the internet.

Small things that add up to a breach

Three issues nobody would have escalated, chained into a full takeover.

04LIKE FOR LIKE

Faster than a consultancy. Deeper than a scanner.

HUMAN PENTEST
AUTOMATED SCANNER
CIPHER
Time to results
Two to six weeks
Hours, shallow
Hours, in depth
Cadence
Once or twice a year
Continuous
Continuous
Business logic flaws
Yes, if scoped
No
Yes, by reasoning
Knowledge retained
Leaves with the team
None
Compounds per target
Cost per assessment
Tens of thousands
Low, and low value
A fraction, every week

Run it against your own estate.

One authorised target and a scope is enough to see this on your own estate.

GET ACCESS